CWE-158
24 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-158page 1 of 1
- CVE-2009-1537HIGHCVSS 8.8EG 9.0⚠ KEV2009-05-29
Unspecified vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 allows remote attackers to execute ar…
- CVE-2020-14500CRITICALCVSS 10.0EG 10.02020-08-25
Secomea GateManager all versions prior to 9.2c, An attacker can send a negative value and overwrite arbitrary data.
- CVE-2020-5363HIGHCVSS 8.6EG 8.62020-06-10
Select Dell Client Consumer and Commercial platforms include an issue that allows the BIOS Admin password to be changed through Dell's manageability interface without knowledge of the current BIOS Admin password. This could potentially all…
- CVE-2020-7928MEDIUMCVSS 6.5EG 6.52020-11-23
A user authorized to perform database queries may trigger a read overrun and access arbitrary memory by issuing specially crafted queries. This issue affects MongoDB Server v4.4 versions prior to 4.4.1; MongoDB Server v4.2 versions prior t…
- CVE-2022-20812CRITICALCVSS 9.0EG 6.52022-07-06
Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow a remote attacker to overwrite arbitrary files or conduct null byt…
- CVE-2022-20813CRITICALCVSS 9.0EG 5.92022-07-06
Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow a remote attacker to overwrite arbitrary files or conduct null byt…
- CVE-2022-31223LOWCVSS 2.3EG 2.32022-09-12
Dell BIOS versions contain an Improper Neutralization of Null Byte vulnerability. A local authenticated administrator user could potentially exploit this vulnerability by sending unexpected null bytes in order to read memory on the system.
- CVE-2022-41716HIGHCVSS 7.5EG 7.52022-11-02
Due to unsanitized NUL values, attackers may be able to maliciously set environment variables on Windows. In syscall.StartProcess and os/exec.Cmd, invalid environment variable values containing NUL values are not properly checked for. A ma…
- CVE-2023-5719HIGHCVSS 8.8EG 8.82023-11-06
The Crimson 3.2 Windows-based configuration tool allows users with administrative access to define new passwords for users and to download the resulting security configuration to a device. If such a password contains the percent (%) chara…
- CVE-2024-0408MEDIUMCVSS 5.5EG 5.52024-01-18
A flaw was found in the X.Org server. The GLX PBuffer code does not call the XACE hook when creating the buffer, leaving it unlabeled. When the client issues another request to access that resource (as with a GetGeometry) or when it create…
- CVE-2024-10921MEDIUMCVSS 6.8EG 6.82024-11-14
An authorized user may trigger crashes or receive the contents of buffer over-reads of Server memory by issuing specially crafted requests that construct malformed BSON in the MongoDB Server. This issue affects MongoDB Server v5.0 versions…
- CVE-2024-9026LOWCVSS 3.3EG 3.32024-10-08
In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using PHP-FPM SAPI and it is configured to catch workers output through catch_workers_output = yes, it may be possible to pollute the final log or remov…
- CVE-2025-14388CRITICALCVSS 9.8EG 9.82025-12-23
The PhastPress plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read via null byte injection in all versions up to, and including, 3.7. This is due to a discrepancy between the extension validation in `getExtensionForUR…
- CVE-2025-1936HIGHCVSS 7.3EG 7.32025-03-04
jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it was ignored when retrieving the content from the archive, but the fake extension after the null was used to determine the type of content. Th…
- CVE-2025-47812CRITICALCVSS 10.0EG 10.0⚠ KEV2025-07-10
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges…
- CVE-2025-55113CRITICALCVSS 9.0EG 9.02025-09-16
If the Access Control List is enforced by the Control-M/Agent and the C router is in use (default in Out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions; non-default but configurable using …
- CVE-2025-61985LOWCVSS 3.6EG 3.62025-10-06
ssh in OpenSSH before 10.1 allows the '\0' character in an ssh:// URI, potentially leading to code execution when a ProxyCommand is used.
- CVE-2025-66263HIGHCVSS 7.5EG 7.52025-11-26
Unauthenticated Arbitrary File Read via Null Byte Injection in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform Null byte injecti…
- CVE-2025-9648HIGHCVSS 8.7EG 0.02025-09-29
A vulnerability in the CivetWeb library's function mg_handle_form_request allows remote attackers to trigger a denial of service (DoS) condition. By sending a specially crafted HTTP POST request containing a null byte in the payload, the s…
- CVE-2026-23863MEDIUMCVSS 6.5EG 6.52026-05-01
An attachment spoofing issue in WhatsApp for Windows prior to v2.3000.1032164386.258709 could have allowed maliciously formatted documents with embedded NUL bytes in the filename to be shown in the application as one type of file but run a…
- CVE-2026-41256MEDIUMCVSS 5.5EG 5.52026-05-11
jq is a command-line JSON processor. In 1.8.1 and earlier, Top-level jq programs loaded from a file with -f are truncated at the first embedded NUL byte on current upstream HEAD. A crafted filter file such as . followed by \x00 and arbitra…
- CVE-2026-43859LOWCVSS 3.7EG 3.72026-05-04
mutt before 2.3.2 sometimes uses strfcpy instead of memcpy for the IMAP auth_cram MD5 digest.
- CVE-2026-43861LOWCVSS 3.7EG 3.72026-05-04
mutt before 2.3.2 does not check for '\0' in url_pct_decode.
- CVE-2026-43895MEDIUMCVSS 4.4EG 4.42026-05-11
jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-language level, but later resolves those paths through C string operations during module and data-file lookup. This creates …
Map vulnerabilities like CWE-158 to your infrastructure
EchelonGraph correlates every CVE — across CWE-158 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →